Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
Quarantine notifications and the extra clicks are controlled by quarantine policies and anti-spam policies. To reduce the noise and make this behave more like traditional junk mail handling, the IT team can adjust two main things:
- Reduce what gets quarantined vs. sent to Junk Email
- In anti-spam policies, the action for spam/high-confidence spam/bulk can be changed from Quarantine message to Move message to Junk Email folder where allowed.
- For example, spam with SCL 5–6 and high confidence spam with SCL 7–9 are, by default, either sent to Junk or quarantined depending on policy (Standard/Strict). These defaults can be relaxed so more goes straight to Junk instead of quarantine.
- This immediately reduces the number of items that ever generate quarantine notifications.
- Reference: spam actions and SCL behavior are described in Spam confidence level (SCL) in cloud organizations and Anti-spam protection in cloud organizations.
- Tune or disable quarantine notifications for users
- Quarantine notifications (the digest emails that are filling the inbox) are controlled by quarantine policies assigned to anti-spam/anti-phishing features.
- In supported protection features, quarantine policies define:
- What users can do (view/release/delete) and
- Whether they receive quarantine notifications at all.
- The IT team can:
- Turn off quarantine notifications for certain quarantine reasons (for example, bulk or spam), or
- Use more restrictive quarantine policies so only admins see and manage certain quarantined items, and users get fewer or no digests.
- Reference: Manage quarantined messages and files as a user and Anti-spam protection in cloud organizations.
- Shift review work from users to admins (optional)
- By default, messages quarantined for high confidence phishing, malware, or mail flow rules are only visible to admins, not users. The same model can be extended via quarantine policies so that more categories are admin-only.
- Admins then periodically review quarantine in the Microsoft Defender portal and release legitimate messages in bulk, instead of every user clicking through digests.
- Admins can also:
- Release messages and submit them to Microsoft for analysis.
- Create temporary allow entries in the Tenant Allow/Block List for known-good senders to reduce future false positives.
- Reference: Manage quarantined messages and files as an admin and How to handle legitimate emails getting blocked (false positives) using Microsoft Defender for Office 365.
- Accept that some quarantine is mandatory
- Malware and high-confidence phishing are always quarantined and cannot be fully turned off for security reasons. However, these categories typically should not generate frequent user notifications if quarantine policies are tuned so that admins, not end users, handle them.
- Reference: Quarantined email messages in cloud organizations.
Practical direction for the IT team
- Review current anti-spam policies and preset security policies (Standard/Strict) and decide where Junk Email is acceptable instead of quarantine for spam/bulk.
- Review and adjust quarantine policies to:
- Disable or reduce quarantine notifications for low-risk categories (e.g., bulk), and/or
- Make more categories admin-only so users are not prompted to review them.
- Ensure admins regularly monitor quarantine in the Defender portal and use submissions and allow entries to reduce false positives over time.
This approach keeps strong protection for true threats while significantly reducing quarantine digests and the number of clicks required in daily work.
References:
- Quarantined email messages in cloud organizations
- Manage quarantined messages and files as a user
- Manage quarantined messages and files as an admin
- How to handle legitimate emails getting blocked (false positives) using Microsoft Defender for Office 365
- Anti-spam protection in cloud organizations
- Spam confidence level (SCL) in cloud organizations